CVE-2026-6045
authorDebian LibreOffice Maintainers <debian-openoffice@lists.debian.org>
Mon, 25 May 2026 11:04:39 +0000 (13:04 +0200)
committerRene Engelhard <rene@debian.org>
Mon, 25 May 2026 11:04:39 +0000 (13:04 +0200)
commitf7be701e3f0896a1b65ff141a5e60254f950e098
treecfc00f45049d132bdc433804d8e895ea9b1c9b7b
parent37e3dda772842ada32889081110b1f642b06c272
CVE-2026-6045

CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read

CVE-2026-6045 EMF+ Heap-buffer-overflow in EMFPBrush::Read
A nested format problem tucked away in the rendering path, probably
need to add something dedicated to the simpler fuzzer to force that
render path to be exercised.

From 279c7ea61829efe5cabc5832d06e1833ad28379f Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Caol=C3=A1n=20McNamara?= <caolan.mcnamara@collabora.com>
Date: Thu, 9 Apr 2026 20:00:38 +0100
Subject: [PATCH] check that the file can provide the claimed data

and make sure we initialize these locals

Change-Id: Ifa899e36f678216574364e5206037ab57b2d19d9
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203577
Tested-by: Jenkins
Reviewed-by: Xisco Fauli <xiscofauli@libreoffice.org>
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Reviewed-on: https://gerrit.libreoffice.org/c/core/+/203628
Signed-off-by: Xisco Fauli <xiscofauli@libreoffice.org>
Gbp-Pq: Name CVE-2026-6045.diff
drawinglayer/source/tools/emfpbrush.cxx
drawinglayer/source/tools/emfppen.cxx